86Articles
6Categories
2025-08-27Date
🐛
Citrix NetScaler ADC and Gateway Hit by Ongoing Attacks Exploiting 0-Day RCE
🐛
IPFire Firewall Admin Panel Vulnerability Enables Persistent JavaScript Injection
🐛
NVIDIA NeMo AI Curator Vulnerability Allows Code Execution and Privilege Escalation
🐛
Over 28,000 Citrix devices vulnerable to new exploited RCE flaw
KEV
🐛
Russia-based Yandex employee oversees open-source software approved for Department of Defense use
🐛
Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424
⚠️
LLMs easily exploited using run-on sentences, bad grammar, image scaling
⚠️
Kubernetes Security: Wie Sie Ihre Cluster (besser) absichern
⚠️
Critical Chrome Use-After-Free Flaw Enables Arbitrary Code Execution
⚠️
Hackers Abuse Compromised OAuth Tokens to Access and Steal Salesforce Corporate Data
⚠️
5 ways to improve cybersecurity function while spending less
⚠️
A Simple Phrase Defeats GPT5 Security
⚠️
Only 49% of companies to increase cyber budget after a breach
⚠️
New Cache Deception Attack Exploits Miscommunication Between Cache and Web Server
⚠️
CISA Issues New ICS Advisories on Critical Vulnerabilities and Exploits
⚠️
vCISO Benefits as the CISO Becomes Strategic and the Board's Responsible for Security ... - BSW #410
⚠️
ShadowCaptcha Exploit: Massive WordPress Site Compromise Used to Execute Malicious Commands on Victims
⚠️
Salesloft OAuth Breach via Drift AI Chat Agent Exposes Salesforce Customer Data
⚠️
Multiple Vulnerabilities in NetScaler ADC and NetScaler Gateway Could Allow for Remote Code Execution
⚠️
Nagios Flaw Enables Remote Attackers to Run Arbitrary JavaScript via XSS
⚠️
Citrix Patches Exploited NetScaler Zero-Day
KEV
⚠️
PromptLock: First AI-Powered Ransomware Emerges
⚠️
New Malware Exploits TASPEN Legacy Systems to Target Indonesian Elderly
⚠️
Fachkräftemangel bedroht Cybersicherheit
⚠️
Why zero trust is never 'done' and is an ever-evolving process
⚠️
Storm-0501 debuts a brutal hybrid ransomware attack chain
⚠️
Cephalus Ransomware Exploits RDP for Initial Access in Latest Attack Campaign
⚠️
Hundreds of Salesforce Customers Hit by Widespread Data Theft Campaign
⚠️
Someone Created First AI-Powered Ransomware Using OpenAI's gpt-oss:20b Model
⚠️
Whistleblower: DOGE put Social Security database covering 300 million Americans on insecure cloud
⚠️
CISA and Partners Release Joint Advisory on Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage Systems
⚠️
FreePBX servers hacked via zero-day, emergency fix released
KEV
⚠️
Critical Zip Slip Bug Enables Malicious File Manipulation on Unzip
⚠️
Smashing Security podcast #432: Oops! I auto-filled my password into a cookie banner
⚠️
The Prevalence of Web-Based RCE Vulnerabilities
⚠️
The Prevalence of Web-Based RCE Vulnerabilities
⚠️
Risky Business #804 -- Phrack's DPRK hacker is probably a Chinese APT guy
📢
Docker security advisory (AV25–546)
📢
Joint cyber security advisory on worldwide network compromises by People’s Republic of China state-sponsored actors
📢
CISA and Partners Release Joint Advisory on Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage Systems
📢
Global Salt Typhoon hacking campaigns linked to Chinese tech firms
📢
Cisco security advisory (AV25-547)
📢
Drupal security advisory (AV25-548)
📢
CISA and Partners Providing Real-Time Incident Response to Cyber Attack on State of Nevada
🔥
TheSqua.re - 107,041 breached accounts
🔥
Home Assistant + Ubiquiti + AI = Home Automation Magic
🔥
Underground Ransomware Gang Unleashes Innovative Tactics Targeting Global Organizations
🔥
We Are Still Unable to Secure LLMs from Malicious Inputs
🔥
Nevada State Offices Closed Following Disruptive Cyberattack
🔥
Anthropic: Claude was weaponized for sophisticated cybercrimes, including a “vibe-hacking” data extortion scheme
🔥
Healthcare Services Group data breach impacts 624,000 people
🔥
Nx compromised: malware uses Claude code CLI to explore the filesystem
🔥
ShadowSilk Hits 36 Government Targets in Central Asia and APAC Using Telegram Bots
🔥
Anthropic Disrupts AI-Powered Cyberattacks Automating Theft and Extortion Across Critical Sectors
🔥
Storm-0501’s evolving techniques lead to cloud-based ransomware
🔥
Cephalus ransomware: What you need to know
🔥
IT system supplier cyberattack impacts 200 municipalities in Sweden
🔥
FBI says China’s Salt Typhoon hacked at least 200 US companies
🔥
Experimental PromptLock ransomware uses AI to encrypt, steal data
🔥
Chinese Hacker Suspect Arrested in South Korea Over Major Financial Cyberattack
🔥
Storm-0501 hackers shift to ransomware attacks in the cloud
🕵️
ISC Stormcast For Wednesday, August 27th, 2025 https://isc.sans.edu/podcastdetail/9588, (Wed, Aug 27th)
🕵️
The entire US Social Security database was uploaded on a random cloud server, Whistle-Blower Says
🕵️
The entire US Social Security database was uploaded on a random cloud server, Whistle-Blower Says
🕵️
DOGE Allegedly Uploaded SSA’s Live Numident Database to Unsecured Cloud Server
🕵️
Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra
🕵️
Spotify Launches Direct Messaging Feature Amid Security Concerns
🕵️
Infostealers: The Silent Smash-and-Grab Driving Modern Cybercrime
🕵️
TAG-144: Actors Attacking Government Entities With New Tactics, Techniques, and Procedures
🕵️
95% of the Grid Runs on Unencrypted Protocols 😱
🕵️
US sanctions fraud network used by North Korean ‘remote IT workers’ to seek jobs and steal money
🕵️
What are You Working on Wednesday
🕵️
🧠 Fuzzing Isn’t Just Science… It’s Experience
🕵️
Microsoft ranked number one in modern endpoint security market share third year in a row
🕵️
Back to School: Cybersecurity Education for All Ages
🕵️
Magic Quadrant for Hybrid Mesh Firewall
🕵️
China-Linked Hackers Hijack Web Traffic to Deliver Backdoor
🕵️
PCI Wants Security Training for Humans… What About AI?
🕵️
Hackers Weaponize Trust with AI-Crafted Emails to Deploy ScreenConnect
🕵️
BlueHat Asia 2025: Closing soon: Submit your papers by September 5, 2025
🕵️
BlueHat Asia 2025: Closing soon: Submit your papers by September 14, 2025
📡
Interesting Technique to Launch a Shellcode, (Wed, Aug 27th)
📡
The 5 Golden Rules of Safe AI Adoption
📡
A Bold New Look for a Bold Future: Sophos’ Reimagined Brand
📡
BadCam attack: malicious firmware in "clean" webcams
📡
Don’t let “back to school” become “back to (cyber)bullying”